The agent responsible to create, change, maintain and tear down access routes with new credentials, tokens, policies, etc inside net-kingdom. Ops-mason is responsible to build the security infrastructure as required and defined by architecture documents as a base for ops-warden..
Find a file
tegwick f90644e8c0 feat(mason): scoped, named OpenBao sessions instead of borrowing yours
Handing an agent an operator session gives it everything you have, for
as long as you have it, and every action lands in the audit log as you.

scripts/bao-session.sh grant <task> mints a separate token into
~/.claude-bao-token — your ~/.vault-token is untouched and the two
revoke independently. 45 minutes, max one hour, display_name
claude-<task> so an audited action is attributable to a piece of work.

policies/ops-mason-build.hcl is what makes the scope real. It allows the
phase-2 survey (sys/mounts, sys/auth, policy list), policy and auth-role
creation, KV metadata reads, and short-lived test tokens for positive
and negative capability checks. It denies every read of */data/* on
platform, operators and secret.

That denial is the point: SCOPE.md says ops-mason never touches secret
values, and until now that was a promise kept by whoever was driving.
An explicit deny outranks any grant, including one added to this policy
later by mistake. The one time the line was crossed is recorded in
plans/state-hub-forge-derivation-read.md §8; under this policy it would
have been refused rather than recorded.

sys/mounts/* is deliberately absent — enabling a mount is a
railiance-platform act, and a grant that needed it should be recognised
as a broader thing rather than folded in here.

Also fixes the WSL2 login trap: bao login's browser launch fails under
gio, so the script prints the URL plainly instead of appearing to hang.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 3377672@bnt-lap001
Assistant-Session: 15463ccf-238f-4e13-b163-93aa25c6d166
2026-08-28 11:04:26 +02:00
bundles build: add guarded Kubernetes plane executor 2026-08-22 11:23:38 +02:00
docs build: provision and verify Whitehat foundational plane 2026-08-22 11:26:49 +02:00
intakes Close legacy identifier intake 2026-08-22 23:21:23 +02:00
manifests/whitehat-plane build: add guarded Kubernetes plane executor 2026-08-22 11:23:38 +02:00
plans feat(mason): deliver and verify the forge read credential 2026-08-27 23:46:42 +02:00
policies feat(mason): scoped, named OpenBao sessions instead of borrowing yours 2026-08-28 11:04:26 +02:00
scripts feat(mason): scoped, named OpenBao sessions instead of borrowing yours 2026-08-28 11:04:26 +02:00
src/ops_mason build: provision and verify Whitehat foundational plane 2026-08-22 11:26:49 +02:00
tests build: provision and verify Whitehat foundational plane 2026-08-22 11:26:49 +02:00
workplans feat(mason): deliver and verify the forge read credential 2026-08-27 23:46:42 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-27 22:49:39 +02:00
.gitignore intake: hand off legacy MASON identifier scheme 2026-08-22 11:33:34 +02:00
.repo-classification.yaml chore(registrar): bind MASON-IN-0001 residual 2026-08-22 11:34:25 +02:00
AGENTS.md feat(mason): scoped, named OpenBao sessions instead of borrowing yours 2026-08-28 11:04:26 +02:00
INTENT.md Real build executed for real (MASON-WP-0001-T05, MASON-WP-0001 done 5/5) 2026-07-27 01:25:14 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 00:42:40 +02:00
pyproject.toml build: add guarded Kubernetes plane executor 2026-08-22 11:23:38 +02:00
README.md build: add guarded Kubernetes plane executor 2026-08-22 11:23:38 +02:00
SCOPE.md Tighten the ops-warden boundary after reviewing its actual repo 2026-07-27 00:44:37 +02:00
WORK-RECORDS.md chore(work-records): regenerate after MASON-WP-0003-T02 2026-08-27 22:49:56 +02:00

ops-mason

The builder of NetKingdom security infrastructure — creates, changes, maintains, and tears down access routes, credentials, tokens, and policies so that ops-warden always has something real to route to.

The four-phase process

  1. Construction plan — given an access demand, draft what needs building, respecting/extending/compacting existing structure first.
  2. Review and optimize — self-review the plan against what already exists, for consistency and ease of use.
  3. Executive summary — the one mandatory human decision gate: render who gets what access, for how long, and what it costs to reverse.
  4. Build — once approved, execute the plan.

See INTENT.md for the full responsibility boundary against ops-warden, OpenBao, flex-auth, and key-cape.

Guarded Kubernetes planes

Small Kubernetes security foundations can use the fail-closed ops-mason plane workflow. It pins source manifests and object identities, validates cluster context/RBAC/dependencies/drift, requires an approved construction plan plus exact digest for apply, and produces metadata-only evidence and a non-executing rollback plan.

See docs/kubernetes-plane.md.